ESG & Sustainability

Frameworks we cover and how ActiveERM helps you track and report ESG with evidence.

The EU Corporate Sustainability Reporting Directive (CSRD) requires in-scope companies to report on sustainability using the European Sustainability Reporting Standards (ESRS). Frameworks such as GRI (Global Reporting Initiative), SASB (Sustainability Accounting Standards Board), and TCFD (Task Force on Climate-related Financial Disclosures) provide widely used metrics for environmental, social, and governance disclosure. SFDR (Sustainable Finance Disclosure Regulation) affects financial market participants. Carbon footprint (Scope 1, 2, 3), materiality, and impact metrics need consistent data and evidence. ActiveERM helps you track ESG data and report with evidence linked to your GRC framework. Explore our ESG & Sustainability page for carbon, materiality, and reporting.

ESG reporting is becoming mandatory in many jurisdictions. Connecting ESG metrics to your risk and control framework ensures data quality and auditability. ActiveERM supports GRI, SASB, TCFD, and CSRD-aligned reporting from one platform.

Key regulations & official links

Explore ESG & Sustainability

CSRD and the ESRS

The Corporate Sustainability Reporting Directive requires in-scope companies to report sustainability information according to the European Sustainability Reporting Standards (ESRS), in the management report, in a machine-readable format, and subject to assurance.

The ESRS comprise cross-cutting standards (ESRS 1 general requirements, ESRS 2 general disclosures) and topical standards across environment (climate, pollution, water and marine, biodiversity, resource use and circular economy), social (own workforce, workers in the value chain, affected communities, consumers and end-users) and governance (business conduct).

Two features change how the work is organised. Reporting is subject to assurance, beginning with limited assurance — meaning every number needs a defensible trail. And the scope is determined by a double materiality assessment, so the assessment itself becomes an auditable artefact rather than an internal planning exercise.

Note that CSRD scope and timing have been subject to legislative amendment, including the 2025 "omnibus" proposals. Confirm your applicable wave and first reporting year against the current national transposition rather than the original directive text.

Double Materiality Is a Risk Assessment

Double materiality asks two questions:

  • Impact materiality — how the company affects people and the environment, considering severity (scale, scope, remediability) and, for potential impacts, likelihood.
  • Financial materiality — how sustainability matters affect the company's development, performance and position, considering magnitude and likelihood.

A matter is material if it meets either test. In practice both are risk assessments with the same structure your enterprise risk process already uses — likelihood against consequence, scored on defined scales, with thresholds.

Teams that run double materiality inside their existing ERM methodology finish faster and produce defensible output, because the scales, escalation thresholds and review cadence are already agreed and already audited. Teams that invent a parallel scoring system spend the first two months arguing about scales, and then have to defend a bespoke method to an assurance provider.

The assessment must be documented: stakeholder engagement, the matters considered, scoring, thresholds, and the resulting list of material topics with the disclosures they trigger.

Scope 1, 2 and 3 Emissions

The GHG Protocol splits emissions into three scopes:

ScopeWhat it coversTypical difficulty
1Direct emissions from owned or controlled sourcesManageable — fuel and refrigerant data
2Indirect emissions from purchased energyManageable — needs location- and market-based figures
3All other value-chain emissions, across 15 categoriesHard — depends on data you do not control

Scope 3 is where credibility is won or lost. Two calculation approaches dominate: spend-based (activity spend × emission factor — quick, low accuracy) and activity-based (physical quantities × factors — more accurate, more data). Most organisations begin spend-based and migrate the material categories to activity-based over time.

What assurance requires is not perfect data. It is disclosed method, disclosed factor source and version, and consistency between periods, with restatements visible as restatements. An estimated figure with a documented method is defensible; a precise-looking figure with no provenance is not.

GRI, SASB, TCFD and SFDR

GRI is the most widely used global standard for impact reporting, organised as universal, sector and topic standards, with a multi-stakeholder audience.

SASB standards, now under the ISSB, are industry-specific and investor-focused, concentrating on financially material sustainability topics. They map closely to ESRS financial materiality.

TCFD structured climate disclosure across governance, strategy, risk management, and metrics and targets. The TCFD itself has been disbanded, with monitoring transferred to the ISSB — but its four-pillar structure survives inside IFRS S2 and the ESRS climate standard, so work done against TCFD is not wasted.

SFDR applies to financial market participants and advisers, governing sustainability-related disclosures for products and entities, including principal adverse impact indicators.

Most organisations report against several. The mappings between them are well established, so the practical approach is to collect each datapoint once and map it to every framework that requires it — the same logic that applies to controls in information security compliance.

Building the Evidence Trail

Sustainability data is the least mature data in most organisations, and it is now subject to assurance. What that demands:

  1. Provenance for every figure — source system or supplier, submission date, and the request it answers.
  2. Method and factor version recorded alongside estimates.
  3. Immutability — submissions versioned, never overwritten.
  4. Controls over completeness and accuracy, with owners, frequencies and test results, exactly as for financial data.
  5. Linkage to the risk register, so a supplier data failure is an assessed risk rather than a red cell on a dashboard.

Supplier ESG data is the weakest link, because it originates outside your control environment. The machinery that already governs security questionnaires applies unchanged.

How ActiveERM Supports ESG Reporting

The ESG module runs double materiality on the same methodology as the risk register, tracks Scope 1, 2 and 3 with recorded methods and factor versions, and maps datapoints to ESRS, GRI, SASB and TCFD so each is collected once.

Because it sits on the GRC platform, sustainability controls live in the same library as security and financial controls, supplier ESG assessments resolve to the same third-party record as security and procurement assessments, and the assurance provider pulls from one evidence store.

See also our guides to GRC and ESG integration and getting started with ESG reporting.

One platform for all your frameworks.

View all regulationsRequest Demo